> The only real way to do that is to make the enclave keys write-only.
That's where you are wrong.
You could install a pubkey in the bios that allowed decryption (by making the symmetric key of enclaves available through encryption with the pubkey). Then the user can choose whether he wants debuggability (by keeping the private key) or security against rubberhose-cryptanalysis (by discarding the key)